Privacy Policy
Benloop ("we", "us" or "our") — the registered Ontario business name under which NorthLawn LP, a Delaware limited partnership registered extra-provincially in Ontario, carries on business — provides a service that allows individuals to view the health and dental benefit entitlements available to them under their own group insurance plans, to receive reminders before those entitlements lapse, and to receive relevant offers, availability and openings from clinics selected using their coverage and claims information (the "Service"). Clinics pay Benloop subscription fees, and those fees are the reason the Service is provided to individual members at no charge; Section 6 sets out what a clinic does and does not receive.
This Privacy Policy describes how we collect, use, disclose and safeguard personal information in connection with the Service. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA") and applicable provincial privacy legislation. Certain of our communications are also subject to Canada's Anti-Spam Legislation ("CASL").
By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy. Capitalized terms not defined here have the meanings given to them in our Terms of Service.
1. Personal information we collect
We collect the following categories of personal information:
- Account information. Your name, email address, telephone number, account credentials for the Service, and the clinic (if any) through which you registered.
- Benefit information. Coverage categories, annual maximums, amounts used and remaining, shared category limits, plan reset dates, your date of birth where your insurer supplies it, and the first three characters of your postal code so we can suggest clinics near you, retrieved from your insurer at your direction.
- Claims information. Approximately the preceding twelve (12) months of claims submitted under your plan, including the provider or clinic, the date of service, the service claimed, and the amounts claimed and paid.
- Clinic attendance information. The clinic you name when we ask where you attend, and the service you attend it for. We record the clinic's name, the treatment, and an identifier for that clinic's location. Where you tell us which clinic a change in your balance went to, we also record the amount, where you name a single clinic, and the period in which the change occurred.
- Spending record. Where you choose to keep a record of health expenses your plan did not cover, the date, description and amount of each entry you type in. We do not decide whether any entry qualifies for a tax credit or any other purpose.
- Plan member information. Where your insurer's response identifies other persons covered under your plan, the name of, the relationship to you of, and the date of birth of, those persons, which determines how two plans coordinate and whether a person can consent for themselves; and where you invite an adult so covered, the email address you supply for that purpose.
- Referral request information. Where you ask us to suggest a provider, the type of service sought, your full postal code, and any free-text information you elect to submit.
- Location information. The first three characters of your postal code, which you provide when you register and which we may also receive from your insurer as described above. We use it to determine whether you are eligible for the Service, and to suggest clinics near you. We do not ask for your street address. We ask for your full postal code only when you ask us to suggest a provider, and we keep it with that request.
- Waitlist information. Where the Service is not available in your province and you ask to be notified, your email address, that province, and the wording you were shown. We use it only to tell you once if the Service becomes available there. You are not a member, and we hold no benefit or claims information about you.
- Consent records. The version, text and timestamp of each consent you provide.
- Technical and usage information necessary to operate, secure and administer the Service, including records of your interaction with links contained in our communications.
- Site analytics. Aggregate measurements of visits to our web pages (the page visited, the referring site, approximate location derived from network address, and browser and device type), collected by our hosting provider without cookies and without any identifier that would allow you to be recognised across sites. Where a web address itself identifies you, as an unsubscribe or invitation link does, that identifier is removed in your browser before any measurement is transmitted, and we do not transmit the contents of any web address query string.
We do not collect or retain clinical records, diagnoses, chart notes or other information created by a health care provider in the course of treatment. We do not retain the credentials you use to authenticate with your insurer (see Section 4).
2. Purposes and legal basis
Because benefit and claims information is sensitive personal information, we rely on your express consent, obtained at registration and recorded as described in Section 8. We collect, use and disclose personal information only for the following purposes:
- to establish, administer and secure your account;
- to retrieve, display and maintain your benefit and claims information;
- to send you reminders and related communications before your coverage lapses, which may include offers, availability or openings from clinics;
- to decide which clinics to offer you, using your benefit categories, the amounts remaining to you, the dates on which your coverage resets, and the providers you have previously claimed against;
- to measure whether those communications were effective, including by recording that a link was followed;
- to produce the aggregate, de-identified reporting described in Section 6;
- to respond to a referral request you submit;
- to keep the spending record you choose to maintain, and to send you a yearly summary of it before tax season; and
- to comply with applicable law and to establish, exercise or defend legal claims.
We will not use personal information for a new purpose without first obtaining your consent, except where permitted or required by law.
3. Consent, and withdrawal of consent
Your consent to the Service is a single consent covering the collection, use and disclosure described in this Policy, including the communications referred to in Section 2. Those communications form part of the Service, and we do not offer a version of the Service without them. You may, however, turn them off at any time and retain everything else, as described below.
The communications we send are commercial electronic messages within the meaning of CASL and are sent on the basis of your express consent. The sender is Benloop, of 18 King Street East, Suite 1400, Toronto, ON M5C 1C4. Each message identifies the sender, states that mailing address, and contains an unsubscribe mechanism. We send a summary of your coverage about once a month, sometimes a text before a benefit expires, a yearly summary of your spending record before tax season, and a short follow-up after you follow a booking link. Standard message and data rates may apply to text messages.
You can stop the messages without closing your account. Every message we send contains an unsubscribe link, and your account settings carry the same control. Using either one stops our reminders and offers and leaves everything else in place: your account remains open, your benefit information remains available to you, and you can turn the messages back on at any time. Stopping the messages is not a withdrawal of consent to the Service and does not delete anything.
Certain messages continue in any event, because they are administrative rather than commercial: a notice that the benefit information we hold for you has gone out of date and can be refreshed, notices concerning your account and its security, confirmations of an action you requested, and notice of a change to this Policy or our Terms. Such notices contain no clinic, no offer and no booking link.
Withdrawal of consent to the Service is a distinct and more consequential step. Because consent to the Service is a single consent, withdrawing it ends your use of the Service; we will delete your stored account, benefit and claims information and cease all communications in accordance with Section 9. You may do so at any time, subject to legal or contractual restrictions and reasonable notice, using the option in your account settings or by contacting us at privacy@benloop.ca. This step cannot be undone.
4. Access to your insurer's member portal
Where you elect to connect a plan, you exercise your own entitlement to obtain the personal information your insurer holds about you: you supply your own credentials, you initiate each retrieval, and we act on your behalf, as your agent, on a read-only basis, solely to retrieve the information described in Section 1. We do not submit claims, initiate transactions, or make any change to your insurer account. Section 4 of our Terms of Service sets out the basis of that access and the licence you grant us in respect of the information so obtained.
The credentials you provide for that purpose are transmitted to us over an encrypted connection, used solely to complete a single retrieval session, and discarded. They are not stored in any database, log, error report or analytics record, and we are not able to reproduce them. You will be asked to re-enter them on any subsequent retrieval.
5. Other persons covered under your plan
An insurer's response may include information respecting a spouse, dependant or other person covered under your plan. Unless you have expressly added such a person to your account, we discard their benefit information at the point of retrieval and retain only their name, their relationship to you and their date of birth, for the purpose of allowing you to add them.
Claims records cover the plan as a whole. Your insurer returns the claims made under your plan as a single record covering everyone insured under it, and does not offer that record one person at a time. We retain it as part of your plan's information, encrypted as described in Section 8. We use it only to identify the clinics and services used under your plan. It is never disclosed to a clinic, it is never used to produce benefit figures or communications respecting a person you have not added, and it is deleted with the rest of your information under Section 9. Any person covered under your plan may ask us to delete the plan's claims record, at privacy@benloop.ca.
A parent or guardian may provide consent in respect of a child under the age of 18. An adult covered under your plan must provide their own consent, and you must not add such a person without their authority. Where you invite such a person, we retain the address you supply and whether the invitation was accepted, until you cease to be a member or either of you asks us to delete it.
Household sharing. Where you link your account to another adult member and both of you agree, each of you can see what the other's plan covers, so that we can tell you which plan to claim from first. That sharing is a separate consent, recorded like the others, and either of you can end it at any time in settings without affecting the rest of your account.
6. How Benloop is paid, and what clinics receive
Clinics pay us, and their fees are the reason the Service is free to you. A clinic subscribes to Benloop, and a subscribing clinic is one we are able to offer you a booking with. Which clinics we show you is therefore shaped by which clinics subscribe, as well as by the benefit categories, remaining amounts, reset dates and previous providers described in Section 2. We state this expressly because a clinic we suggest may reasonably appear to you to be a recommendation, and you should be aware that a commercial relationship underlies it. A clinic's subscription purchases the opportunity to be included in offers. It does not purchase information about you, and it does not purchase any influence over which members receive communications.
Clinics. We disclose to clinics only aggregate, de-identified information respecting groups of their patients who use the Service, together with aggregate results of campaigns. A clinic does not receive, and cannot obtain from us, your name, your individual balances, your claims, or confirmation that you are a member of the Service. Where fewer than five (5) individuals would be represented in an aggregate figure, that figure is withheld. These restrictions are applied at the database level and not solely within the application. Aggregation reduces, but cannot entirely eliminate, the possibility that a clinic with detailed knowledge of its own patients could draw inferences from figures it observes over time.
Bookings. We do not make appointments on your behalf. Our communications may link to a clinic's own booking facility, at which you contract directly with that clinic. We record that a link was followed. We do not transmit your name, contact information, balances, expiry dates or insurer to any clinic in connection with a booking or otherwise.
Service providers. We engage third parties to perform functions on our behalf, including hosting, data storage, message delivery, and website analytics. Such parties are permitted to process personal information only as necessary to provide those functions and are bound by confidentiality and security obligations.
Legal and corporate. We may disclose personal information where required or permitted by law, including in response to a valid demand from a court, regulator or law enforcement authority, and in connection with a proposed or completed corporate transaction, subject to appropriate safeguards.
We do not sell personal information, and we do not disclose personal information for third-party advertising purposes.
7. Our relationship with clinics
We act on your behalf and not on behalf of any clinic. We are not a clinic's agent or service provider in respect of your personal information, we do not act as an information manager or affiliate for any health information custodian, and we have no access to any clinic's records or practice management systems. Clinics purchase access to aggregate reporting and to communications addressed to their patients as a group; they do not thereby obtain access to your personal information.
8. Safeguards and records of consent
We maintain administrative, technical and physical safeguards proportionate to the sensitivity of the information, including encryption in transit, access controls on a least-privilege basis, segregation of sensitive processing, and practices designed to exclude personal information from application logs and error reports.
Your benefit information, claims information and referral request information are encrypted at rest using keys not held within the database. Your name, email address and telephone number are stored without field-level encryption and are protected by access controls. No method of transmission or storage is entirely secure, and we do not warrant absolute security.
For each consent you provide, we retain the version identifier, the verbatim text displayed to you, and the date and time. Where the text changes, a new version is issued; existing records are not amended.
9. Retention
We retain benefit and claims information for so long as your account remains active. If you close your account or withdraw consent, we delete your account information, benefit information and claims information immediately, in a single operation, and we retain a record that the deletion was carried out.
Encrypted backup copies of our database, made for disaster recovery, are replaced on a rolling basis, and a copy made before a deletion may hold the deleted information until it is replaced. Backups are encrypted, access to them is restricted, and they are used for no purpose other than restoring the Service after a failure. If a backup is ever restored, deletions carried out after it was made are applied again.
We retain, notwithstanding the foregoing, records of consents given and withdrawn and of unsubscribe requests, for the purpose of demonstrating compliance, and records of any breach of security safeguards for twenty-four (24) months as required by PIPEDA.
10. Storage and cross-border processing
Account, benefit and claims information is stored on servers located in Canada. Because Benloop is operated by a limited partnership established in Delaware, notwithstanding its registration and business address in Ontario, that information may nonetheless be reached by legal process directed at us in that jurisdiction. Our handling of it remains subject to PIPEDA.
Our hosting, database and key-management providers are companies established in the United States. The database and the key that decrypts your benefit information are held in Canadian data centres.
Service providers outside Canada. We use two service providers established in the United States to deliver communications to you: Resend, for email, and Twilio, for text messages. They receive only what is necessary to send you a message, being your email address or telephone number and the contents of that message. They do not receive your benefit or claims information. They are not authorized to use what they receive for any purpose other than delivering the message.
We also use Google Places, established in the United States, to help you find your clinic when you tell us where you attend. When you type into that field, the text you type is sent to Google so it can suggest matching clinics. Your request reaches Google from our servers rather than from your device, so Google does not receive your network address, and it is not told who you are, which plan you hold, or anything about your coverage or claims. Google is not authorized to use what it receives for any purpose other than returning suggestions. We keep only Google's identifier for the clinic you choose, and we ask Google for that clinic's current name and address each time we need to display them rather than storing them. Where you ask us to suggest a provider, we also send Google one search naming the type of service and your postal code; we do not send your note, and we do not identify who asked.
Both providers engage their own subprocessors. Resend's subprocessors operate in the United States. Twilio's subprocessors operate in the United States and in Australia, Belgium, Chile, Denmark, Finland, Germany, Ireland, Japan, the Netherlands, Poland, Singapore, Switzerland, Taiwan and the United Kingdom. Each provider publishes and maintains its own current list. Your email address or telephone number and the contents of your message may therefore be collected, used, disclosed or stored in any of those countries. Personal information processed in a foreign jurisdiction may be accessible to the courts, law enforcement and national security authorities of that jurisdiction.
We also use Anthropic, established in the United States, where you ask us to suggest a provider. To prepare the suggestions that a person at Benloop reviews before they reach you, our servers send Anthropic the type of service sought, your postal code and any note you wrote; we do not send your name, your contact details, or any of your benefit or claims information. Anthropic is not authorized to use what it receives for any purpose other than answering our request, does not use it to train its models, and deletes it within 30 days.
Our Privacy Officer can answer your questions about the collection, use, disclosure or storage of personal information by our service providers outside Canada, and can provide written information about our policies and practices in respect of those providers, at privacy@benloop.ca.
11. Your rights
- Access. You may request access to the personal information we hold about you and information about how it has been used and disclosed.
- Correction. You may request correction of inaccurate or incomplete personal information.
- Withdrawal of consent. You may withdraw consent as described in Section 3.
- Deletion. You may request deletion of your personal information, subject to Section 9.
- Unsubscribe. Every commercial electronic message contains an unsubscribe mechanism. We give effect to unsubscribe requests promptly and in any event within ten (10) business days, as CASL requires.
We will respond to a request within thirty (30) days, or such longer period as PIPEDA permits, and will advise you if an extension is required. We may require information sufficient to verify your identity before acting on a request.
12. Breach of security safeguards
Where a breach of security safeguards creates a real risk of significant harm to an individual, we will notify affected individuals and report the breach to the Office of the Privacy Commissioner of Canada, and to any applicable provincial regulator, as required by law.
13. Changes to this Policy
We may amend this Policy from time to time. The "last updated" date above will be revised, and where a change is material we will provide notice by a reasonable means before it takes effect.
14. Contact
Our Privacy Officer is accountable for our compliance with this Policy and with PIPEDA, and may be reached at privacy@benloop.ca. Questions, access or correction requests, and complaints respecting our handling of personal information should be directed to that address.
Our mailing address is Benloop, 18 King Street East, Suite 1400, Toronto, ON M5C 1C4.